WGU D487 OA TEST 3 2026 FINAL EXAM
PREPARATION GUIDE WITH KEY CONCEPT
BREAKDOWN AND PRACTICE ITEMS
◉ What is the product risk profile?
Answer: A security assessment deliverable that estimates the actual
cost of the product.
◉ A software security team member has been tasked with creating a
deliverable that provides details on where and to what degree
sensitive customer information is collected, stored, or created within
a new product offering. What does the team member need to deliver
in order to meet the objective?
Answer: Privacy impact assessment
◉ What is the first phase in the security development life cycle?
Answer: A1 Security Assessment
◉ What are the three areas of compliance requirements?
Answer: Legal, financial, and industry standards
◉ What term refers to how the system should function based on the
environment in which the system will operate?
,Answer: operational requirements
◉ During what phase of SDL do all key stakeholders discuss, identify,
and have common understandings of the security and privacy
implications, considerations, and requirements?
Answer: A1 Security Assessment
◉ What are the three areas of focus in secure software
requirements?
Answer: Gathering the software requirements, data classification,
and managing data protection requirements
◉ During what phase of SDL is an initial project outline for security
milestones developed and integrated into the development project
schedule?
Answer: A1 Security Assessment
◉ What term means requirements that describe what the system
will do and its core purpose?
Answer: functional requirements
◉ What term means requirements that describe any constraints or
restrictions on a design but do not impact the core purpose of the
system
, Answer: non-functional requirements
◉ What term is a process that evaluates issues and privacy impact
rating in relation to the privacy of personally identifiable
information in the software?
Answer: privacy impact assessment
◉ What term helps to determine the actual cost of the product from
different perspectives?
Answer: product risk profile
◉ What term is a table that lists all of the security requirements
Answer: requirement traceability matrix
◉ What term is the environment in which the product will operate
and potential threats in that environment?
Answer: threat profile
◉ What phase of the SDL examines security in terms of business
risks, with inputs from the software security team and key
stakeholders?
Answer: A2 Architecture Phase
PREPARATION GUIDE WITH KEY CONCEPT
BREAKDOWN AND PRACTICE ITEMS
◉ What is the product risk profile?
Answer: A security assessment deliverable that estimates the actual
cost of the product.
◉ A software security team member has been tasked with creating a
deliverable that provides details on where and to what degree
sensitive customer information is collected, stored, or created within
a new product offering. What does the team member need to deliver
in order to meet the objective?
Answer: Privacy impact assessment
◉ What is the first phase in the security development life cycle?
Answer: A1 Security Assessment
◉ What are the three areas of compliance requirements?
Answer: Legal, financial, and industry standards
◉ What term refers to how the system should function based on the
environment in which the system will operate?
,Answer: operational requirements
◉ During what phase of SDL do all key stakeholders discuss, identify,
and have common understandings of the security and privacy
implications, considerations, and requirements?
Answer: A1 Security Assessment
◉ What are the three areas of focus in secure software
requirements?
Answer: Gathering the software requirements, data classification,
and managing data protection requirements
◉ During what phase of SDL is an initial project outline for security
milestones developed and integrated into the development project
schedule?
Answer: A1 Security Assessment
◉ What term means requirements that describe what the system
will do and its core purpose?
Answer: functional requirements
◉ What term means requirements that describe any constraints or
restrictions on a design but do not impact the core purpose of the
system
, Answer: non-functional requirements
◉ What term is a process that evaluates issues and privacy impact
rating in relation to the privacy of personally identifiable
information in the software?
Answer: privacy impact assessment
◉ What term helps to determine the actual cost of the product from
different perspectives?
Answer: product risk profile
◉ What term is a table that lists all of the security requirements
Answer: requirement traceability matrix
◉ What term is the environment in which the product will operate
and potential threats in that environment?
Answer: threat profile
◉ What phase of the SDL examines security in terms of business
risks, with inputs from the software security team and key
stakeholders?
Answer: A2 Architecture Phase